0

Some jerk attacked my server, and I was reading the logs, when I saw "JYADXW" where the HTTP verb GET/POST/OPTIONS normally reside. What is this request? what does it mean?

malicious IP Here - - [26/Sep/2014:06:12:01 -0400] "JYADXW / HTTP/1.1" 403 520 "-" "Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 5.1; Trident/4.0)"
j0h
  • 203
  • 1
  • 7
  • 520 CloudFlare's reverse proxies to signal an "unknown connection issue between CloudFlare and the origin web server" to a client in front of the proxy. – j0h Sep 29 '14 at 14:50

1 Answers1

2

You can check the full list of HTTP request methods in RFC 7231.

An attacker was probably assessing what your web server does with an invalid request.

Giovanni Tirloni
  • 5,693
  • 3
  • 24
  • 49